HR 4005 Introduced - Enhancing K–12 Cybersecurity
Last month, Rep Matsui (D,CA) introduced HR 4005, the Enhancing K–12 Cybersecurity Act. The bill would require CISA to establish a school cybersecurity information exchange, a cybersecurity incident registry, and a K–12 cybersecurity technology improvement program. The bill would authorize $10 million per year through 2023 to fund such programs. This bill is not related to S 1917, K–12 Cybersecurity Act of 2021, in anyway.
Definitions
Section 6 provides definitions of six critical terms used throughout the bill. They are all defined by reference to other entries in the U.S. Code.
Section 3(e) provides the definition of ‘covered entity’ used exclusively in Section 3, Cybersecurity incident registry. That definition incorporates the following:
An elementary school,
A secondary school,
A local educational agency,
A State educational agency, and
An educational service agency.
School Cybersecurity Information Exchange
Section 2 of the bill would require CISA to work with one or more information sharing and a analysis organizations to “focus specific attention on the needs of K–12 organizations with regard to cybersecurity”. This would include a new web site to “disseminate information, cybersecurity best practices, training, and lessons learned tailored to the specific needs, technical expertise, and resources available to K–12 organizations”.
Cybersecurity Incident Registry
Section 3 of the bill would require CISA to establish “a voluntary registry of information relating to cyber incidents affecting information technology systems owned or managed by a covered entity”. The information would be used to:
Improve data collection and coordination activities related to the nationwide monitoring of the incidence and impact of cyber incidents affecting a covered entity,
Conduct analyses regarding trends in cyber incidents against such entity,
Develop systematic approaches to assist such entity in preventing and responding to cyber incidents,
Increase the awareness and preparedness of a covered entity regarding the cybersecurity of such covered entity, and
Identify, prevent, or investigate cyber incidents targeting a covered entity.
K–12 Cybersecurity Technology Improvement Program
Section 4 of the bill would require CISA to establish a cybersecurity technology improvement program to “to deploy cybersecurity capabilities to address cybersecurity risks and threats to information systems of elementary schools and secondary schools”. The program would address:
The development of cybersecurity strategies and installation of effective cybersecurity tools tailored for K–12 organizations,
Making available cybersecurity services that enhance the ability of K–12 schools to protect themselves from ransomware and other cybersecurity threats, and
Continuing training opportunities on cybersecurity threats, best practices, and relevant technologies for K–12 schools.
Moving Forward
Matsui is not a member of either the House Homeland Security Committee or the Education and Labor Committee to which this bill was assigned for consideration. Four of her cosponsors {Rep Katko (R,NY), Rep Langevin (D,RI), Rep Garbarino (R,NY), Rep McCaul (R,TX)} are members of the Homeland Security Committee (and Katko is the Ranking Member) so there is probably sufficient influence available to see this bill considered in Committee. I see nothing in this bill that would draw organized opposition.
I suspect that there would be sufficient bipartisan support for this bill in Committee that the House leadership would move this bill to the floor of the House under the suspension of the rules process.
Commentary
Those who have been reading my legislative commentaries over the years will be little surprised to hear that I have concerns about the definitions that are being used (or more accurately, not used) in this bill. There are two common cybersecurity terms used in this bill; ‘information system’ and ‘information technology’. The definition of these terms can have a significant impact on the scope of coverage of the bill, and in this case, they are left undefined.
There is one school of thought that wants to see Congress provide broad guidance to regulatory agencies and for those agencies to work out the details of how that guidance will be applied and updated in a changing environment. I tend to favor an approach that has Congress specify what it wants regulated and then allows the regulating agency to determine how those rules would be applied. A key to that approach is the use of definitions to set the scope of a regulatory scheme.
Having said that I would like to offer the following definitions for the two cybersecurity terms used in this bill that would be added to §6:
(7) INFORMATION SYSTEM – the term ‘information system’ has the meaning given that term in 6 USC 1501, and specifically includes building control systems and security systems, and
(8) INFORMATION TECHNOLOGY – the term ‘information technology’ has the meaning given that term in 40 USC 11101 as it would apply to any organization defined in this section.
The other problem with this bill is its continued reliance on the concept of ‘voluntary information sharing’. We have been trying to rely on voluntary reporting about cybersecurity incidents for over ten years now and it has been an abject failure. The cybersecurity incident registry in §3 will only be successful if the reporting is mandatory.